macOS proxy settings are stored per network service, and Safari, Chrome and most apps follow them. On macOS 13 and later, open System Settings > Network, select your service (for example Wi-Fi), click Details…, then Proxies. Turn on Web proxy (HTTP) and Secure web proxy (HTTPS), enter the host and HTTP port from your ProxyHive order, switch on Proxy server requires password, add the username and password, and click OK. https://api.ipify.org then shows the IP you bought.

Steps checked against Apple's Mac User Guide on 2026-09-29.

Before you start

  1. Buy an IP and open the order in the dashboard at https://app.proxyhive.io.
  2. Copy HOST, PORT, USERNAME and PASSWORD. Every ISP or datacenter IP is its own endpoint, and the order lists separate HTTP, HTTPS and SOCKS5 ports.
  3. Choose username and password, or add your public IP to the order's IP allowlist and leave the password switch off.
  4. Know which network service you use. Settings are stored per service, so a proxy on Wi-Fi does nothing on Ethernet.

macOS proxy settings in System Settings

  1. Choose Apple menu > System Settings and click Network in the sidebar.
  2. Click the service you are connected through, such as Wi-Fi or Ethernet.
  3. Click Details… (for Wi-Fi, next to the connected network), then Proxies.
  4. Turn on Web proxy (HTTP). Enter HOST as the server and the HTTP port as the port.
  5. Turn on Proxy server requires password and enter the Username and Password from the order.
  6. Turn on Secure web proxy (HTTPS) and enter the same server, port and credentials.
  7. Optional: tick Exclude simple hostnames, and list anything that should skip the proxy in Bypass proxy settings for these hosts & domains, separated by commas.
  8. Click OK.

"Secure web proxy (HTTPS)" means the proxy used for https:// sites, not a different kind of server. The HTTP port handles both, with https:// traffic tunnelled and still encrypted end to end.

On macOS 12 and earlier the same fields are under System Preferences > Network > Advanced > Proxies, and you click Apply after OK.

SOCKS proxy

To use SOCKS5 instead, turn on SOCKS proxy, enter HOST with the SOCKS5 port, and add the password if needed; leave the two web proxies off. Some apps cannot authenticate to SOCKS5 (Chrome is one), so the HTTP pair is the safer default. HTTP vs SOCKS5 proxies goes through when SOCKS5 is worth it.

Authentication in Safari and Chrome

Safari uses the credentials you saved in System Settings. Chrome follows the system proxy too, but may still show its own sign-in box the first time the proxy asks; enter the same username and password.

Apps that neither read stored credentials nor prompt fail with a 407 error. For those, use the IP allowlist on the order, or route them with Proxifier, which stores credentials and applies rules per app.

Set the proxy with networksetup

The same settings from Terminal, useful for scripts or several Macs. First find the exact service name:

networksetup -listallnetworkservices

Then set, check and switch off the proxies (replace Wi-Fi with your service):

networksetup -setwebproxy "Wi-Fi" HOST PORT on USERNAME PASSWORD
networksetup -setsecurewebproxy "Wi-Fi" HOST PORT on USERNAME PASSWORD
networksetup -setproxybypassdomains "Wi-Fi" "*.local" "169.254/16"
networksetup -getwebproxy "Wi-Fi"
networksetup -setwebproxystate "Wi-Fi" off
networksetup -setsecurewebproxystate "Wi-Fi" off

The on argument turns authentication on; with the IP allowlist, use off and drop the username and password. Commands typed this way stay in your shell history, so clear the lines with a password or use the allowlist on shared machines. scutil --proxy prints the proxy configuration macOS is using right now.

Verify the exit IP

In Safari or Chrome, open https://api.ipify.org?format=json. The ip value should be the IP on your order.

curl in Terminal ignores the system proxy, which makes it a clean second check of the proxy on its own:

curl -x http://HOST:PORT -U "USERNAME:PASSWORD" "https://api.ipify.org?format=json"

The curl guide has more on testing from the command line.

Several IPs

The system proxy is one address per service. For several static IPs at once, give each browser or browser profile its own proxy, or use Proxifier rules per app. Holding a few fixed IPs, one per account or project, is often cheaper than a pool: see buying a single static IP and ISP proxies, sold one IP at a time.

Troubleshooting

  • Nothing changed. You set the proxy on a service you are not using. Check the one at the top of the Network list.
  • The password prompt repeats, or 407. Wrong username or password, or the order uses the allowlist and your current IP is not on it.
  • Connections fail entirely. Wrong port, or the SOCKS5 port entered as a web proxy.
  • Some traffic skips the proxy. Check the bypass list and Exclude simple hostnames.

For status codes and error pages, see the proxy error codes guide. Apple's proxy settings article is the official reference, and the Windows guide covers the same setup on a PC.